Hacking 6.2.0 released

NeoSnipe

New Member
Newbie
Joined
Nov 20, 2018
Messages
4
Trophies
0
Age
35
XP
59
Country
France
Check out videos on youtube about how to use RCM mode. The black screen is normal, you need to learn the additional steps.

Thanks.

I did that last days, press vol + and power quickly to boot. For you it’s not a problem about this new update ? I should have something on screen ?
 

NeoSnipe

New Member
Newbie
Joined
Nov 20, 2018
Messages
4
Trophies
0
Age
35
XP
59
Country
France
Nop bought it one year ago.

So i found my problem.. forgot to rename in payload.bin

Sorry

--------------------- MERGED ---------------------------

So now i have message after unpackaging os in red :

Error package2 magic invalid

This time it’s the new firmware nintendo who’s block install ?

Thanks again :)
 

Aniblaze

Well-Known Member
Newcomer
Joined
Oct 23, 2009
Messages
75
Trophies
1
XP
508
Country
Netherlands
Please keep us updated!
I'm holding off. Some other people updated their system before me, and had the same setup (SD emuNAND 6.1, OFW 6.2). It works, but as soon as you enter sleep mode on the 6.1 emunand and try to wake up the system, it apparently does a fuse check, forcing a shutdown. So until SX OS fixes that, I'm not updating the system to 6.2 yet. I am running SD emuNAND right now though. It's just that my OFW is still on 6.1 as well.
 

palantine

Well-Known Member
Member
Joined
Oct 5, 2014
Messages
174
Trophies
0
Age
38
XP
593
Country
Italy
The new key generation explained:

The switch has an Nvidia coprocessor ( a second processor) inside of it called the TSEC or Falcon that handles cryptographic operations like AES and verifying signatures. This processor is ordinarily supplied a firmware when the switch boots and then hands over the TSEC key to the boot loader so it can decrypt and load the rest of the firmware.

What was changed in 6.2 is that the TSEC firmware now derives one of the decryption keys internally rather than letting the boot loader do it. This means that despite having full control over the boot process, the derivation of this key now happens secretly where we cannot see it.

I'm looking at the TSEC firmware now to research this process but it may be simply out of our reach unless we can exploit or trick the TSEC into doing what we want or leaking the info. Here is a screenshot I took of reverse engineering the 6.2 TSEC firmware.

Screen Shot 2018-11-20 at 6.47.45 PM.png
 

The_Green_Nerd

Well-Known Member
Newcomer
Joined
Mar 9, 2018
Messages
62
Trophies
0
Age
36
XP
636
Country
Netherlands
Just asking: not using SX-OS atm. But planning to do in the future with emunand. Can I savely update to 6.2.0 and still able to install SX-OS and launch a CFW (don't mind if it's 6.1.0)?
 

palantine

Well-Known Member
Member
Joined
Oct 5, 2014
Messages
174
Trophies
0
Age
38
XP
593
Country
Italy
Just asking: not using SX-OS atm. But planning to do in the future with emunand. Can I savely update to 6.2.0 and still able to install SX-OS and launch a CFW (don't mind if it's 6.1.0)?

I spoke to someone on discord who apparently was running SX emunand on 6.1 and OFW on 6.2. Its just one person but it makes sense that this would work.
 

The_Green_Nerd

Well-Known Member
Newcomer
Joined
Mar 9, 2018
Messages
62
Trophies
0
Age
36
XP
636
Country
Netherlands
I spoke to someone on discord who apparently was running SX emunand on 6.1 and OFW on 6.2. Its just one person but it makes sense that this would work.
yeah, but 6.2 also burns a fuse. So you must start 6.1 always from RCM and sleep mode won't work. And I don't have a NAND back-up atm. Which means I must wait until I got my NAND backed up, before I can update. Or are their other ways around?

Also, if I understand you correctly. Hacking 6.2.0 is gonna be a pain in the butt because decrypting is done within another chip on the SoC?
 

flatty69

Well-Known Member
Newcomer
Joined
Sep 2, 2018
Messages
52
Trophies
0
Age
41
XP
244
Country
Colombia
Just a heads up Dont do this and think your safe i had my switch like this and hit update to see if this did block the update and nope it didnt it update to 6.2 from 6.1 so DONT THINK THIS WILL KEPP YOU SAFE DONT HIT THE UPDATE EVEN IF YOU DID THIS TO YOUR DNS "
  1. Change DNS to Manual.
  2. Set the primary DNS server to 163.172.141.219.
  3. Set the secondary DNS 45.248.48.62.
  4. Press the save button and then B to return to the network list.
  5. EPIC FAILL
 
D

Deleted User

Guest
The new key generation explained:

The switch has an Nvidia coprocessor ( a second processor) inside of it called the TSEC or Falcon that handles cryptographic operations like AES and verifying signatures. This processor is ordinarily supplied a firmware when the switch boots and then hands over the TSEC key to the boot loader so it can decrypt and load the rest of the firmware.

What was changed in 6.2 is that the TSEC firmware now derives one of the decryption keys internally rather than letting the boot loader do it. This means that despite having full control over the boot process, the derivation of this key now happens secretly where we cannot see it.

I'm looking at the TSEC firmware now to research this process but it may be simply out of our reach unless we can exploit or trick the TSEC into doing what we want or leaking the info. Here is a screenshot I took of reverse engineering the 6.2 TSEC firmware.

View attachment 149848

Rip
 

Jordan9716

Active Member
Newcomer
Joined
Nov 9, 2015
Messages
31
Trophies
0
Age
33
XP
118
Country
United States
The new key generation explained:

The switch has an Nvidia coprocessor ( a second processor) inside of it called the TSEC or Falcon that handles cryptographic operations like AES and verifying signatures. This processor is ordinarily supplied a firmware when the switch boots and then hands over the TSEC key to the boot loader so it can decrypt and load the rest of the firmware.

What was changed in 6.2 is that the TSEC firmware now derives one of the decryption keys internally rather than letting the boot loader do it. This means that despite having full control over the boot process, the derivation of this key now happens secretly where we cannot see it.

I'm looking at the TSEC firmware now to research this process but it may be simply out of our reach unless we can exploit or trick the TSEC into doing what we want or leaking the info. Here is a screenshot I took of reverse engineering the 6.2 TSEC firmware.

View attachment 149848

God speed man. Best of luck cracking it!

--------------------- MERGED ---------------------------

Just a heads up Dont do this and think your safe i had my switch like this and hit update to see if this did block the update and nope it didnt it update to 6.2 from 6.1 so DONT THINK THIS WILL KEPP YOU SAFE DONT HIT THE UPDATE EVEN IF YOU DID THIS TO YOUR DNS "
  1. Change DNS to Manual.
  2. Set the primary DNS server to 163.172.141.219.
  3. Set the secondary DNS 45.248.48.62.
  4. Press the save button and then B to return to the network list.
  5. EPIC FAILL

Same thing happened to me man :/ I was in CFW, I really hate myself for getting careless like this.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Xdqwerty @ Xdqwerty:
    good night
  • BakerMan @ BakerMan:
    as to you
  • K3Nv2 @ K3Nv2:
    How do you know if the night will be good when you're asleep
  • BakerMan @ BakerMan:
    because i didn't say i was asleep
  • BakerMan @ BakerMan:
    i said i was sleeping...
  • BakerMan @ BakerMan:
    sleeping with uremum
  • K3Nv2 @ K3Nv2:
    Even my mum slept on that uremum
  • TwoSpikedHands @ TwoSpikedHands:
    yall im torn... ive been hacking away at tales of phantasia GBA (the USA version) and have so many documents of reverse engineering i've done
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
    The Real Jdbye @ The Real Jdbye: never had that i don't think